Detection Engineer and Escalation Analyst
Il y a 1 jour
Mons, Wallonia, Belgique
WLG
Temps plein
Gratuit avec email ou Google
Enregistrez cette offre et organisez votre recherche
Créez un compte gratuit pour enregistrer des offres d'emploi, créer des alertes et revenir à cette liste depuis votre tableau de bord.
Gratuit avec email ou Google
Second line is where an alert stops being noise and becomes a decision.
You would be the technical escalation point in a large defence security operations centre inMons, Belgium — validating what the first line produces, digging into the cases they cannot close,and building the detections that stop the same thing reaching them twice.
What you would be doing
Reviewing and validating investigations, supporting first-line analysts so that alert closures,escalations, evidence and notes meet the standard — complete, accurate and procedurally sound
Acting as the technical escalation point for security monitoring: in-depth log analysis andthreat triage across Splunk Enterprise Security, Splunk SOAR and Microsoft Sentinel, plus thesupporting data sources and security appliances, and deciding what goes to incident handling
Providing on-call cover as part of a 24x7 roster, so second-line escalations are answered roundthe clock
Designing, developing, testing and maintaining detection rules, alerts and analytics across themonitoring tool-set — tuning logic, thresholds, allow-lists, suppression and severity so falsepositives fall and coverage of new threats rises
Giving first-line analysts regular, constructive feedback and coaching on technique, analyticalapproach and reporting, and helping new joiners find their feet
Supporting the duty second-line analyst through the week — watching open tasks, chasing pendingactions, and flagging anything that threatens service continuity
Taking part in purple-team exercises to test and improve detection coverage
Working with the threat hunting team to turn their findings into automated detections whereverthat is possible
Contributing to service improvement: finding the workflow inefficiencies, the monitoring blindspots, and saying what should change
Writing and updating the operational documentation, procedures, run-books and knowledge-basearticles the whole team relies on
Representing the monitoring function in project planning, implementation and transition, sovisibility requirements are considered early, and advising on detection content, log-sourceintegration and security-tool configuration
Working with colleagues across the wider security organisation and with external partners
Ad-hoc work when it is needed — special investigations, projects, whatever keeps the operationeffective
What you would bring
At least three years hands-on in a security operations centre or a closely related monitoringenvironment
A proven expert-level record of analysing complex security incidents and writing clear,authoritative reports and recommendations for the teams and partners who act on them
Real fluency extracting, normalising and interrogating raw log data from varied sources —Windows event logs, Linux syslog, Sysmon, endpoint detection platforms such as Microsoft Defender,SentinelOne or CrowdStrike — using Splunk, Microsoft Sentinel or Elastic Kibana. Filtering,correlating and visualising events to verify an alert, reconstruct what an attacker did acrosshosts, and hand over evidence someone can act on
Hands-on packet capture analysis with Wireshark, tcpdump or Zeek — pulling traffic apart tocorroborate an alert and rebuild a timeline
The ability to turn attacker techniques and threat intelligence into working detection logic,and to run structured peer reviews of other analysts' investigations that actually find the gaps
Designing, developing and maintaining detections across monitoring, endpoint and cloud securitytooling — Splunk, Microsoft Sentinel, Azure, AWS
Supporting or mentoring less experienced analysts, with feedback they can use
Practical automation work: spotting the repetitive manual task and building the enrichment orworkflow that removes it
Strong written and spoken communication — investigation notes, escalation summaries anddocumentation that read well under pressure
Professional English
A bachelor's degree in a related discipline with three years of related experience — or,exceptionally, five years of extensive and progressive expertise in this kind of work
A relevant certification such as CISSP, CISM, a GIAC credential (GCIH, GCFA, GSEC) or CompTIACySA+
Nice to have
A degree in cyber security, IT or computer science
Time in a regulated, high-control environment — defence, government, financial services orcomparable
Cloud-native security monitoring on Azure or AWS, and hybrid estates
Building detections from network and edge devices such as Cisco, Fortinet, Palo Alto orsimilar
Work for or with a military or governmental organisation
Why this one is worth a look
Detection engineering and deep analysis in the same seat, at a scale where the telemetry isgenuinely interesting and the escalations are real.